Detecting Layer2 Loops
We all too familiar with the devastating impact a talented layer 2 loop could have on a data center lacking sufficient controls and processes. If you are using Cisco Nexus switches in your data center, you would be happy to know that NX-OS offers an interesting new tool you should add to your loop detection list. The somewhat undocumented feature is known as (for the lack of a better name) FWM-Loop Detection. FWM refers to the NX-OS Forwarding Manager. In Syslog it is seen as:
How does it work? When NX-OS detect a series of MAC flap events that exceeds an Cisco defined limit, NX-OS classifies that as a potential layer2 loop. To protect the CPU from continuously updating the CAM table with the same MAC address(es) flapping between interfaces, dynamic MAC address learning is disabled for the entire switch for 3 minutes. This safeguards the switch during that time, if the problem happened to be a once off issue. After 3 minutes dynamic MAC learning is enabled again as normal. If the problem persists, dynamic MAC learning is disabled again.
The FWM-Loop Detection feature is enabled by default and has no configurable metrics that can be set.
Let’s take a look at this in action. For the output below I have induced a physical loop between two Fabric Extender interfaces and disabled all loop prevention mechanisms. The Syslog events are as follow (with the times omitted):
As seen above once detected, the FWM Loop Detection kicks in and disables MAC learning. After 180 seconds MAC learning is enabled and the following Syslog event is generated:
Although this feature (as is today) will not prevent a layer2 meltdown on its own, it certainly does delay the race condition that ultimately ends up total downtime. I would recommend adding the FWM-2-STM_LOOP_DETECT event to your syslog monitoring events since it is a effective early warning system that could help in identifying a potential problem in your data center.
On the negative side, currently the FWM Loop Detect feature disables MAC learning for all VLANs not just the offending VLAN. An enhancement request was logged with vendor-C, to only penalize the offending VLAN . Hopefully this will be available in a future code release.
What is MAC Flapping ?
—> MAC Flapping occurs when a switch receives the frames with same MAC address from different interfaces.
—> There are so many reasons because of which, MAC Address Flapping can occur
i) If you are getting so many MAC Addresses in the switch are flapping then the issue is Layer 2 loop.
ii) NIC Card of the Device is Faulty.
iii) If the device is having two NIC cards and they are connected to switch without EtherChannel or port channel.
Host in Vlan is flapping between port Po1 and Po2
Hello, I'm having a strange issue with dual 2504 WLCs. The WLCs are configured with one operating as the primary, handling all traffic, while the other should only take over if the original fails. After we had some issues reported at the site I took a look at the logs on the main switch. The issue turned out to be something else but I found that the logs were entirely filled up with these messages.
SW_MATM-4-MACFLAP_NOTIF: Host 60f1.8920.2b4b in vlan 50 is flapping between port Po2 and port Po1
May 26 16:56:25: %SW_MATM-4-MACFLAP_NOTIF: Host 28a0.2bb7.0845 in vlan 50 is flapping between port Po1 and port Po2
May 26 16:56:45: %SW_MATM-4-MACFLAP_NOTIF: Host 60f1.8920.2b4b in vlan 50 is flapping between port Po2 and port Po1
May 26 17:25:58: %SW_MATM-4-MACFLAP_NOTIF: Host 3063.6bb2.4ecf in vlan 50 is flapping between port Po1 and port Po2
May 26 18:55:36: %SW_MATM-4-MACFLAP_NOTIF: Host 9060.f13b.0a29 in vlan 50 is flapping between port Po2 and port Po1
This occurs a couple times an hour going back as far as the log stores messages. Each WLC connects to the switch with 3 ports in a port-channel. Ports are configured as such, with 5 being the AP VLAN, and 50 being the Client:
>interface Port-channel1
description Primary-WLC
switchport trunk allowed vlan 5,50,100
switchport mode trunk
!
interface Port-channel2
description HA-WLC
switchport trunk allowed vlan 5,50,100
switchport mode trunk
end
Show interface outputs show no errors or interface resets on the ports themselves. We are using the exact same setup at a similar site, and are not receiving the log messages. So naturally I assume there is a misconfiguration somewhere, but I am getting nowhere comparing WLC and switch configurations looking for differences. Does anyone have any ideas what could cause this?. I can 100% confirm it's not a miswire. Thank you in advance.
termsl
Натолкнулся на такое сообщение в логе коммутатора CISCO:
%SW_MATM-4-MACFLAP_NOTIF: Host 0015.5d00.1207 in vlan 1 is flapping between port Gi2/0/11 and port Gi3/0/24
для того, чтобы прочитать полностью- нажми сюда!
Recent Posts from This Journal
Я их расколдовал
Юра, boud , я еще один контроллер сперва окирпичил, потом зело разозлился, и оба расколдовал, теперь у меня три с последними прошивками)))…
Вкладыши в ящики
Заходил в Метро, прямо около входа были, цапнул с десяток, надо еще взять:
Знатокам пылесосов Festool
Завершил модернизацию, длинною месяца 3 наверное. Теперь пылесос стал еще ебее и удобнее. Попробуй угадать, чем, и да это не циклон.
Какие пупочки- загляденье
Наконец-то дошли руки распаковать и опробовать телвиновский новый контач- подсмотрел у Михалыча bougaev , зело лютый, компактный и хорошо…
И пападробнее
Суммарити: Редуктор с серводвигателем в сборе: Парковка для ручки:
Фрезер почти добил
Воткнул редуктор на серводвигатель автоподачи оси Х и настроил сервопак, все пока работает as is, сопли подбирать и наводить красоту буду в процессе,…